Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

Executive Summary

Researchers discovered that a malicious app installed on a OnePlus 15 running OxygenOS can gain root access without requesting any permissions. By chaining two unpatched vulnerabilities in OnePlus’s software, the attacker can obtain full system control. The flaws also affect other OnePlus devices and OPPO phones, but the company has not yet released a fix.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-24T18:10:18+00:00 - Category: threat-intel

Original Description: A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not

"Work out your own salvation. Do not depend on others."

— Buddha
Source: The Hacker News